IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-23664 HIGH 7.5 microsoft azure_iot_explorer Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2022-29146 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0%
CVE-2022-29144 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0%
CVE-2022-21847 MED 6.5 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 1.0%
CVE-2025-21383 HIGH 7.8 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 1.0%
CVE-2023-35635 MED 5.5 microsoft windows_11_22h2 Windows Kernel Denial of Service Vulnerability 1.0%
CVE-2020-17038 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 1.0%
CVE-2020-0998 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>In a local attack scenario, 1.0%
CVE-2020-0870 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit this vulnera 1.0%
CVE-2020-0838 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log 1.0%
CVE-2020-0782 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog.</p> <p>To exploit this vuln 1.0%
CVE-2026-57982 MED 6.5 microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-54116 MED 6.5 microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-50468 MED 6.5 microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. 1.0%
CVE-2023-36020 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.0%
CVE-2022-30138 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.0%
CVE-2021-21552 MED 5.2 microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and 1.0%
CVE-2025-29840 HIGH 8.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2023-36393 HIGH 7.8 microsoft windows_10_1507 Windows User Interface Application Core Remote Code Execution Vulnerability 1.0%
CVE-2022-41116 MED 5.9 microsoft windows_7 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability 1.0%
CVE-2022-41090 MED 5.9 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability 1.0%
CVE-2024-26257 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.0%
CVE-2023-21712 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1.0%
CVE-2026-58291 MED 6.1 microsoft edge_chromium Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2025-59502 HIGH 7.5 microsoft windows_10_1809 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. 1.0%